By George Norman - Software News Editor
Added on 06 Jul 2009(639 Views)




Security expert Charlie Miller, which you might remember from the PWN2OWN competition where he managed to hack into Apple’s Safari in about 10 seconds, has uncovered a rather nasty security vulnerability affecting the iPhone. The vulnerability that Charlie Miller uncovered refers to the manner in which the iPhone handles text messages (SMS), which in turn could grant a person with malicious intent to gain root access to the device.

Unfortunately for those of you that want more details on the matter, Charlie Miller could not provide in-depth details on the vulnerability he uncovered, for obvious security reasons. If the details were to be released before Apple has time to work on a fix then anyone could potentially exploit this SMS vulnerability.


What we do know is this: the iPhone handles SMS messages in a dangerous manner that could allow a person with malicious intent to remotely install and run unsigned software code with root access on the device. The attacker could for example send software code on the iPhone via SMS and thanks to this malicious code the attacker could turn on the device’s microphone and listen in to your conversation, could turn on the device’s GPS and know precisely where you are, or could add the iPhone to a botnet or distributed denial of service attack.

It sounds gloom, I know, but there is one upside. Charlie Miller does not have an exploit for this vulnerability so far, just a very suspicious crash (he can crash part of the device and temporarily disconnect it from the network). On top of that Apple is reportedly already aware of this issue and is currently working with Miller on a patch. The fix is supposed to be rolled out later this month, before Charlie Miller is due to make a detailed presentation on how to “inject SMS messages into iPhone, Android, and Windows Mobile devices” at the Black Hat 2009 event (25th through 30th of July, Caesar’s Palace, Las Vegas).

In related news, we already know that Apple is working on the iPhone OS 3.1 update. Let’s just hope that alongside the fixes and improvements it has to offer, a fix for this SMS vulnerability is also included.





Don't forget to:

RSS


Tags: Apple, iPhone, SMS, Vulnerability, Charlie Miller

Link to this article:



Add comment:
Name(Required)
Email(Required - Never shown)
Website(Optional)
Comment(Required):

Insert the following code:
Software News
Wolfram Alpha App 1.1 with Better Specialized Keyboards
The team behind computational knowledge engine Wolfram Alpha announced the release of an iPhone specific app last year, in October. The one thing that people complained about at the time...
09 Feb 2010
Linus Shows Nexus One Some Love, Google Shows Nexus One Users Some Love
Linus Torvalds, the father of Linux, says that when he got the original Google Phone, the G1, he was unimpressed. At the time Google gave him the device – that what I meant by “he got the G1”. Linus, who says...
09 Feb 2010
Google Superbowl Ad Draws Attention to the Need for Privacy
Back in January, on International Data Privacy Day, Mountain View-based search engine giant drew attention to its guiding privacy principles. In case you’re not familiar with...
09 Feb 2010
Free Software Alert: EASEUS Partition Master Professional Edition 5.0.1
The latest release of EASEUS Partition Master Professional Edition is version 5.0.1, and the company that developed the software is now giving it away for free. But you need to hurry up. This is a time limited offer...
09 Feb 2010
MSN Games and Windows Live Messenger Welcome FarmVille
The short description of FarmVille is this: “FarmVille is a game where you can farm with your friends.” Basically you get a plot of land and you have to plant crops, harvest them, make money to buy...
09 Feb 2010
Bill Cosby Is Not Dead, Just the Victim of Malware Spreaders
It’s the Kanye West and Johnny Depp story all over again. People with malicious intent have started a rumor that popular comedian and actor Bill Cosby, 72, died of natural causes, in his chair at home....
09 Feb 2010
Recommended Tools
Top Downloads